ISO 22301 · BCMS documentation

Build the BCMS once. Evidence ISO 22301 and DORA with the same documents.

Twenty-two documents and three workbooks covering the documented information ISO 22301:2019 requires, each one carrying both the ISO clauses it satisfies and the DORA articles it evidences at the same time. Plus the instrument that tells you what would fail a Stage 1 review.

52 requirements tracked · 34 mandatory documented information items · clauses 4 to 10 · Word + Excel
Bundle & save:€150 → −15% · €300 → −20% · €500 → −25% · €800 → −30%Applied automatically from 2 products — mix any products.

Read this before you buy anything from anyone

We are not a certification body. Certification against ISO 22301:2019 is granted only by an accredited certification body, after a Stage 1 documentation review and a Stage 2 implementation audit. This pack prepares the documents you present at those audits. No document set can make you certified, and any vendor implying otherwise is selling you something they cannot deliver. What we can do is make sure the documentation is not the thing that fails.

Most entities build this evidence twice

A financial entity subject to DORA has already written a continuity policy, run an impact analysis, tested its plans and reported to its board. ISO 22301 asks for the same substance in a different shape. Building the two separately is the default, and it is pure waste.

The dual mapping is the product

Every document opens with two tables: the ISO clauses it satisfies, and the DORA articles and technical standards it evidences at the same time. Nobody else sells an ISO 22301 pack that is simultaneously a DORA evidence set, because nobody else builds ISO documentation for this audience.

Clause 4.2.2The mandatory legal and regulatory register ships pre-populated with your DORA obligations.
Clause 8.2.2The business impact analysis that feeds your Article 3(22) determination.
Clause 8.4.3.1Incident records that also satisfy DORA Article 11(8).
Clause 8.5The exercise programme that evidences the yearly testing under Article 11(6).
Clause 9.3Management review, which is also your Article 5(2) governance evidence.
Already ISO 27001?One switch marks 20 shared clauses as reusable rather than new work.
What is in the pack
01How to use this toolkit and implementation roadmaporientation
02BCMS manual4.1, 4.4, 8.1
03BCMS scope statement and boundaries4.3
04Business continuity policy5.2
05Roles, responsibilities and authorities5.3, 7.1
06Business continuity objectives and the plan to achieve them6.2
07Competence, awareness and training programme7.2, 7.3
08BCMS communication procedure7.4
09Control of documented information procedure7.5
10Business impact analysis and risk assessment procedure8.2
11Business continuity strategies and solutions8.3
12Incident response structure and activation procedure8.4.2
13Warning and communication procedure8.4.3
14Business continuity plan template8.4.4
15ICT disaster recovery plan template8.4.4, 8.4.5
16Crisis management team charter8.4.2
17Exercise, evaluation and improvement programme8.5, 8.6
18Exercise plan and post-exercise report template8.5
19Monitoring, measurement and evaluation procedure9.1
20Internal audit programme and procedure9.2
21Management review procedure and agenda pack9.3
22Nonconformity and corrective action procedure10.1, 10.2
23Certification readiness workbook (Excel)the instrument
24BCMS registers workbook (Excel)4.2.2, 6.1, 8.2.3
25Records and evidence workbook (Excel)every retain clause
€349 excl. VAT
  • 22 Word documents, editable, with placeholders
  • 3 Excel workbooks including the readiness instrument
  • Every document dual-mapped ISO clause → DORA article
  • Reusable on client engagements
  • Instant delivery, free updates
Get the toolkit

Secure payment by Stripe. VAT invoice issued automatically; EU businesses entering a VAT number get the reverse-charge invoice.

The readiness workbook is the part competitors do not have

A folder of templates tells you what to write. It does not tell you whether you are ready, or what an auditor is about to ask. This one does both.

Stage 1 blockers, flagged

Mandatory documented information that is not yet approved fails a Stage 1 documentation review. The workbook marks each one, so you clear them before you book a certification body rather than after they have invoiced you.

The question the auditor will ask

Every requirement carries the literal Stage 2 question, in the auditor's own framing. The internal audit checklist is generated from the same wording, so auditing yourself rehearses the real thing.

Shared-evidence switch

Already certified to ISO/IEC 27001 or ISO 9001? One answer on the Setup tab marks 20 shared management-system clauses as reusable evidence rather than new work.

Where it sits next to what you may already own

We deliberately do not ship the same file under two products. If you own these, this pack complements them rather than repeating them.

Operational Resilience Assessment (€79)

That toolkit measures your ISO 22301 maturity. This one builds the documentation. No assessment content is duplicated here.

See the assessment toolkits →

Business Impact Analysis Toolkit (€149)

Clause 8.2.2 asks for a BIA. This pack ships the procedure; the BIA workbook is the instrument that produces the output.

See the BIA Toolkit →

Policy & Procedures Pack (€69)

That pack's ICT continuity policy is anchored on DORA Articles 11 and 12. Document 04 here is the organisation-wide BCMS policy clause 5.2 asks for. Different altitude, both stand alone.

See the premium library →

Questions

Does buying this make us ISO 22301 certified?

No. Certification is granted only by an accredited certification body after a Stage 1 and a Stage 2 audit. This pack prepares the documentation you present there and tells you when it is ready. Documentation is the part of a certification project that is predictable; implementation and evidence are yours.

Does DORA require ISO 22301?

No, and holding the certificate does not make you DORA compliant. The two overlap heavily in substance and not at all in form: DORA is supervised, ISO is certified. What overlaps is the evidence, which is why every document here is mapped both ways.

We already hold ISO/IEC 27001. How much of this is new work?

Roughly twenty of the fifty-two requirements are shared management-system clauses — context, leadership, planning, support, performance evaluation and improvement. Set that flag on the readiness workbook and it marks them as reusable evidence. The genuinely new work is clause 8: impact analysis, strategies, plans, response structure and exercising.

How many documents do competitors ship?

Some advertise more files. Count what they are: many packs pad the number with one-page forms. We ship 22 documents, 3 workbooks and roughly 180 pages, we list every one of them above with the clause it satisfies, and we include an instrument none of them have. Compare the list, not the number.

Can consultants use it on client engagements?

Yes. It is licensed to one named purchaser and there is no per-engagement fee. Save a copy per client and replace the placeholders.

What happens when ISO 22301 is revised?

The clause structure lives in one place in our build, so a revision is a rebuild rather than a rewrite of twenty-two documents. Updated editions are emailed to purchasers.

Do we still need to buy the standard?

Yes. ISO 22301:2019 is copyrighted and we do not reproduce its text or its tables. You will need a licensed copy, and your certification body will expect you to have one.

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar